splunk / contentctl

Splunk Content Control Tool
Apache License 2.0
91 stars 23 forks source link

Improve filter macro checking #165

Closed pyth0n1c closed 4 months ago

pyth0n1c commented 4 months ago

Improve checking to ensure that a filter macro is included in each detection and that the filter macro has the proper name (which is deterministically calculated from the name of the detection/filename itself).

pyth0n1c commented 4 months ago

Tests all look good, including against security_content!